-
Posts
645 -
Joined
-
Last visited
-
Days Won
101
Content Type
Profiles
Forums
Downloads
Tutorials
Everything posted by Morpheus
-
Sorry for the delay. There is no event mechanism setup for auto-updating the rules using Pulledpork. This has to be completed manually unless you create something to auto-update. Remember: there needs to be faults checked throughout the complete update process because if one error occurs the Windows Intrusion Detection will shut down without notice. A script would need to very detailed and faults would need to be handled properly.
-
Snort for Windows
Morpheus replied to a5098726s's topic in Discussing Manual Installation for Apache2 with MySQL Logging
Preform a fresh install of Windows 10, and then use this tutorial to install the Windows Intrusion Detection System per the support programs you requested. -
I just tried on a new install of Windows 7 and there is no problem. I'm not sure what your problem could be, but make sure you are running the modder.vbs from a command window with administrator privileges. You might be able to right click the modder.vbs and Run as Administrator. You might mod the modder.vbs file to bypass the check.
-
It might be easier to just start over. You can fix it but it would require reinstalling MySQL from scratch, fixing the password authentication in BASE and Barnyard2 to sync with the MySQL database. Uninstall MySQL Delete the MySQL folder Do section: Installing the MySQL Database Server Do Section: Configuring the MySQL Database Server Do Section: Creating the Windows Intrusion Detection System Databases Do Section: Creating the Windows Intrusion Detection System Database Tables Do Section: Creating the Windows Intrusion Detection System Database Access, and Authenticated Users Do Section: Confirming MySQL and Snort are operational Do Section: Configuring the Windows Intrusion Detection Systems (WinIDS) Security Console Do Section: Configuring Barnyard2 Do Section: Testing the Barnyard2 configuration file Reboot Do Section: Verifying Barnyard2, and Snort is running as a process after rebooting Do Section: Starting the Windows Intrusion Detection Systems (WinIDS) Security Console That should do it?
-
Path issues
Morpheus replied to jrivett's topic in Discussing Manual Installation for Remote Node Logging to MySQL
#1: Original Line(s): var SO_RULE_PATH ../so_rules Change to: # var SO_RULE_PATH ../so_rules Yes, there is a change, as indicated above. #2: Original Line(s): dynamicdetection directory /usr/local/lib/snort_dynamicrules Change to: # dynamicdetection directory /usr/local/lib/snort_dynamicrules Yes, there is a change, as indicated above. Follow the tutorial, and don't make any changes. If you have to make changes there is something wrong. -
Wrong file names?
Morpheus replied to jrivett's topic in Discussing Manual Installation for Remote Node Logging to MySQL
That is correct. Those two files are used by the Reputation preprocessor. Both files needs to exist or there will be a fatal error. -
There is a new tutorial specifically for the slave sensor. Some of the questions above will be moot by using the new tutorial. //--\\ Sourcefire determines which rules are activated for each of the three policies. Note: Rules are managed by using the 4 .conf file located in the pulledpork\etc folder. Read each file for a description. Never modify the winids.rules file at any time. //--\\ Winsnort.com does not furnish script files for automating the processing of the rules. However this doesn't prevent users from posting their script/s. //--\\ PS - Yes, I did see the PM, and will get back to you on that. I'm being squeezed for time in other things right now.
-
No merged.log file
Morpheus replied to Steven's topic in Discussing Manual Installation for IIS with MySQL Logging
The merged log file is where Barnyard2 get the events from. and sends to the specified database. The Waldo file is only created after Snort detects and logs the first event to the merged.log.<time stamp> file. The problem is that Snort has yet to detect any events from the setting specified in the snort.conf. There could be several reasons, but it's ALL related to the Snort, which creates the logs. Try here -
I'm not familiar with AWS. So to make things clearer you are running a Windows slave client sending Barnyard2 data to a MySQL database located on an Amazon EC2 instance. Then you'll have a remote Ubuntu workstation running Snorby and reading the MySQL database from the Amazon EC2 instance. This might be worth writing something up to help others that might be doing what you did.
